<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:55:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05210</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05210</link>
      <description>bdu:2026-05210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05210</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0871 — De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0871</link>
      <description>certfr-2025-avi-0871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0871</guid>
    </item>
    <item>
      <title>cnvd-2025-24143</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-24143</link>
      <description>cnvd-2025-24143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-24143</guid>
    </item>
    <item>
      <title>EUVD-2026-350984</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-350984</link>
      <description>EUVD-2026-350984</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-350984</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58903</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58903</link>
      <description>&lt;p&gt;An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a  Null Pointer Dereference, crashing the http daemon via a specialy crafted request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a  Null Pointer Dereference, crashing the http daemon via a specialy crafted request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58903</guid>
    </item>
    <item>
      <title>GHSA-9rvw-gg78-wfm7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9rvw-gg78-wfm7</link>
      <description>&lt;p&gt;An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a  Null Pointer Dereference, crashing the http daemon via a specialy crafted request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a  Null Pointer Dereference, crashing the http daemon via a specialy crafted request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9rvw-gg78-wfm7</guid>
    </item>
    <item>
      <title>ICSA-25-135-01 — Siemens RUGGEDCOM APE1808 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-135-01</link>
      <description>&lt;p&gt;An insufficiently protected credentials vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server. An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out. A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices. An Authentication Bypass Using an Alternate Path or Channel vulnerability in FortiOS and FortiProxy may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component. An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An insufficiently protected credentials vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server. An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out. A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices. An Authentication Bypass Using an Alternate Path or Channel vulnerability in FortiOS and FortiProxy may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component. An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-135-01</guid>
    </item>
    <item>
      <title>SSA-864900 — SSA-864900: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-864900</link>
      <description>&lt;p&gt;Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-864900</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2283 — Fortinet FortiOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2283</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fortinet FortiOS ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen oder Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fortinet FortiOS ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen oder Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2283</guid>
    </item>
  </channel>
</rss>
